2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13552HIGH8.8A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is ...
CVE-2025-13551HIGH8.8A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an un...
CVE-2025-13550HIGH8.8A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown functi...
CVE-2025-13549HIGH8.8A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNt...
CVE-2025-13548HIGH8.8A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects un...
CVE-2025-13547HIGH8.8A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the fi...
CVE-2025-13546CRITICAL9.8A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by t...
CVE-2025-13545HIGH7.2A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3....
CVE-2025-13544CRITICAL9.8A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is...
CVE-2025-13197Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12561Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-12541Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-13526HIGH7.5The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,...
CVE-2025-13318MEDIUM5.3The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and...
CVE-2025-13136MEDIUM4.3The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing c...
CVE-2025-13384HIGH7.5The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i...
CVE-2025-13317MEDIUM5.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ...
CVE-2025-12877MEDIUM5.3The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized mod...
CVE-2025-12752MEDIUM5.3The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u...
CVE-2025-11186MEDIUM6.4The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-12889MEDIUM5.4With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those ...
CVE-2025-65947HIGH8.7thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resour...
CVE-2025-65946HIGH8.1Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error...
CVE-2025-12888HIGH7.5Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler o...
CVE-2025-12678Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now